shadowbrokers-exploits/oddjob/Not-For-Release/oddjob_v3_x64.exestrings.txt

1110 lines
9.8 KiB
Text
Raw Permalink Normal View History

!This program cannot be run in DOS mode.
b+>D&JP
Rich&JP
.text
`.rdata
@.data
.pdata
@.rsrc
@.reloc
x ATAUAVH
L$(3
yxxxI
A^A]A\
D$ ~>
T$PH
D$PH
T$PH
T$PH
L$PL
D$PL+
L$ H
D$ H
L$dA
D$ H
L$ A
D$dH
T$ H
D$ H
T$ H
L$ A
D$dH
T$dA
D$dH
D$ H
T$ H
D$dH
T$dH
D$dH
T$dH
L$dA
T$ H
D$dH
T$ A
D$ H
L$dH
D$dH
D$ H
D$ H
D$ H
D$dA
D$ H
L$dA
T$ H
T$ H
D$dH
T$ H
D$ H
D$X3
L$XH
T$@H
9\$@
L$XE3
D$PH
L$PH
T$ H
L$PH
;\$@s
L$XH
D$PH
\$HH
SUVWATH
D$HH
L$0L
L$0I;
d$0H
D$0H
L$HH3
PA\_^][
D$HL
L$0L
L$0H
L$HH3
T$0A
;|$0
\$8H
VWATAUAVH
t$`I
D$`H
L$`L
L$`I;
t$`I;
\$hH
0A^A]A\_^
L$8L
D$0E3
L$0H
T$@H
L$0H
L$8H
L$8L
D$0E3
L$0H
T$@H
L$0H
L$8H
UVWH
D$hH
L$hL
D$`H
T$ H
L$`H
t;H;t$`v4H
T$`D
D$PH
L$hH
L$ H
T$`H
\$XH
0_^]
T$ H
T$PH
uf!D$X3
D$\D
D$(D
D$dH
D$hH;D$`v
T$PH+D$`i
WATAUAVAW
\$xL
l$tH
t A;
D$xL
D$xL
\$tH
l$p;
|$t;
L$p;
L$p;
L$(H
L$p;
\$p;
t$xL;
L$pH
\$p;
l$pE9
L$p;
L$(H
9\$tt/H
L$p;
\$pH
\$p;
|$ A
|$ A
L$pH;
gfffD
gfff
gfffH
D$`D
|$XD
t$PD
l$HD
9\$tt>H
|$p;
|$pH;
|$pH
u^H;
L$xH
t$xL;
A_A^A]A\_
[ UVWATAUAVAWH
D$PL
T$pA
l$hH;
L$XI
T$XL
L$pL
l$0E3
L$`D
9|$`u
tNL;
uLL;
r-H;
|$PH
D$hH
L$hM
|$0E3
L$\H
9D$\tN
D$xE3
D$HH
D$@H
l$8H
l$0I
D$hH;
A_A^A]A\_^]
WATAUAVAWH
L$HE
D$ H
L$HH
D$PE3
L$PE3
D$PH
L$HH
D$@E3
L$@H
l$0H
D$(E3
L$@H
l$0H
D$(E3
L$@H
D$(E3
L$@H
D$(E
L$PH
L$@H
L$HH
A_A^A]A\_
UVWATAUAVAWH
D$8E3
L$@E
u#M;
L$(L
|$$E3
L$ M
L$PH
D$ H
DDPfA
D$ #
DLPHc
D$"H
DLPfA
DDPfA
F<fA
l$0L
l$8D
|$$E3
A_A^A]A\_^]
@SUVWATAUAVAWH
D$8E3
T$=E3
-t A;
Ll0I
L$0D
D$"fD9T$4u
fD9T$6
r4Hc
T$ L
L$(D
L$8H3
HA_A^A]A\_^][
H VWATH
D$?H
L$0E
D$ @
L$0E
D$ H
L$0L
L$0H
A\_^
UVWATAUH
D$ A
D$!P
D$"A
D$#Q
D$$A
D$%R
D$&A
D$'S
D$(A
D$)T
D$*A
D$+U
D$,A
D$-V
D$.A
D$/W
D$0U
D$1V
D$2W
D$3R
D$4Q
D$5S
D$6P
D$7j
D$Z
D$^@
T$ H
A]A\_^]
s WATAUAVAWH
|$@fE
|$0H
L$@E
A_A^A]A\_
T$PH
D$P8
L$lD
L$pD
D$XH
D$|H
L$ H
T$PH
t A;
\$0H
s WH
T$DH
9l$Dt
T$@H
L$@H
l$8H
l$0L
l$(H
L$@H
l$8H
l$0L
L$@@
T$@H
L$@H
l$8H
l$0L
l$(H
L$@H
l$8H
l$0L
UVWATAUAVAWH
L$ A
D$0M
|$(H
T$0L
t.L;
T$0L
@A_A^A]A\_^]
x ATAUAWH
\$hD
D$`D
\$@H
l$HH
|$XH
A_A]A\
VWATH
L$"E3
SuTL
L$ H
T$ A
T$*H
A\_^
UVWATAUAVAWH
D$XL
L$0L
D$`I;
D$@I;
L$8M
|$8A
T$HA;
T$HI
L$LA
|$@Ic
T$8I
D$HE
D$(H
T$8L
L$0I
T$8L
L$0M
|$`H
L$XE3
l$XH
D$hH
|$@M;
pA_A^A]A\_^]
l$ VWATH
L$B3
d$0D
D$@H
|$(i
A\_^
WATAUH
D$ A
d$ A
L$hH
D$`E3
\$`E;
L$`H
L$hH
D$`L
D9#v/H
T$pH
A]A\_
t7SH
\$0H
t$8H
L$@H
L$0H
D$HB
L$0H
T$03
T$03
T$0I
*!Nb
\$@H
\$0H
\$0H
t$8H
L$0I
\$0A
t<f;
T$0f
\$`H
l$hH
t$pH
twH;
t$H+
u-fD!
MZuSHc
\$ H
T$pA
D$XE3
T$`H
D$PH
D$HH
D$0H
D$@H
D$(H
D$ L
L$PL
D$XH
T$`3
D$hH
D$p3
D$0A
D$0A
\$0H
\$0H
D$ H
\$ H;
\$@H
t$HH
|$XH
|$ AUH
t,Hc
L$HH!D$ H
\$@H
l$PH
|$XH
D$0H
\$8H
l$@H
t$HH
\$0H
\$0H
l$8H
t$@H
\$0H
l$8H
t$@H
UVWATAUAVAWH
L$p3
L$PD
L$DH
H!l$ E3
t$@H
D$XD
d$Dt=
D$TH
T$TH
d$DH
D$xA
D$\0
t$xH
L$LA
t$@H
l$H+
guKA
l$H~.A
l$HI
L$0H
t$(D
t$@D
D$\-
D$\+
D$\
|$LD
l$PH
t$pE+
L$@L
L$@H
L$\L
|$pt
L$@L
L$XLc
L$XL
L$@L
L$@L
t$@D
l$HH
T$dA
A_A^A]A\_^]
T$pL
D$@A
!D$h!D$P!D$LA
D$DD
T$@H
T$@H
L$HH
L$0H
L$PL
L$(H
L$`L
L$ 3
D$`H
\$0H
\$0H
L$0H
L$0H;
\$8H
\$0H
t$8H
D$p H
D$(H
D$8H
\$0H
D$(L
L$pD
D$8H
\$0H
D$(L
L$pA
\$0H;
L$0H;
\$8H
L$ 3
UVWATAUH
D$8H
D9d$
8\$&H
D$&t18X
t18Y
L$8H3
@A]A\_^]
` AUH
T$ L
\$@H
t$HH
|$PL
d$XH
\$0H
t$8H
\$@A
L$pA
D$@f
T$pH
L$pH
D$8H
D$pt
8csm
@ =
x ATH
\$0H
l$8H
t$@H
\$0H
l$8H
t$@H
9"u 3
\$@H
l$HH
|$PH
x AUH
\$0A
9"u?A
9 t+f
9 t%E
t A93
t$ H
|$(A]
D$HL
L$@E3
D$HH
t>HcD$@L
L$@H
D$HH
\$@A
\$PH
\$0H
l$8H
t$@H
` AUH
D$hH
tHHc
9MZu*9Q<|%
HcA<H
L$8D
\$8L3
\$@H
u,Hc
\$0H
t$8H
|$@H
\$0H
l$8H
t$@H
\$0H
t$8H
|$@H
\$0H
\$0H
9MZu
HcQ<
LcA<E3
@SUH
WATAUAVAWH
)IcyHM
a8M+
A;<$
L$0H
>csm
D$(H
A;<$sr
q I+
A;<$s\H
s8H;
A;<$r
\$@I
A_A^A]A\_
WATAUAVAWH
|$p3
H!t$ E3
|$8D
|$8H
}+Hc
\$@I
A_A^A]A\_
WATAUH
!l$0H9-
H!l$ E3
L$4A
L$ A
D$8H
H!l$ E3
\$PI
A]A\_
T$8L
D$<D
D$8u
D$8H
\$0H
WATAUAVAWH
|$ E3
|$ E3
\$hH
t$pH
0A_A^A]A\_
\$ UVWATAUAVAWH
t$Du
H!t$ E3
l$XMk
T$LH
!t$PE
D$LI
L$@H
\$LD
L$@A
D$`L
D$@A
D$XH
L$PH
T$`I
t$P9l$P
D$XH
L$PH
T$`H
D$@A
f;D$@u:
f;D$@u
|$p3
H!\$ H
D$pD
D$XH
L$HH
T$pI
t$HH
D$pH+
HcD$HH;
|$p3
H!\$ H
D$pD
D$XH
L$HH
T$pI
t3HcL$HH
D$pH+
D$pH
D$XH
L$HD+
l$HD;
H!t$ L
L$HE
t$H3
l$XH
A_A^A]A\_^]
WATAUAVAWH
|$ E3
|$ E3
\$hH
t$pH
0A_A^A]A\_
s'Hc
w&H+
w&H+
l$ VWAUH
L$!H
T$$H
L$ D
9\$ ~
;\$ |
L$0H3
\$pH
l$xH
@A]_^
\$`H
t$hH
L$0I
\$0A
L$0D
~0A;
D$(H
L$0u
D$(H
D$0H
D$ D
L$ 3
D$ D
x ATH
l$8H
t$@H
|$HH
\$0H
L$ D
UVWATAUAVAWH
l$@H
!|$(H!|$ E
t$@H
u"Ic
|$(H
t$ E
L$(H
D$ E
|$@H
l$(H
|$ E
!D$(H
D$(H
D$ E
MHH3
ePA_A^A]A\_^]
L$PI
L$PD
D$0H
\$pI
@UATAUAVAWH
l$0H
\$0H;
d$(H
A_A^A]A\]
L$@A
L$@D
D$(H
\$pH
t$xH
tBSH
K H;
K(H;
K0H;
K8H;
K@H;
KHH;
tuH+
L$0I
D$(H
\$`H
t$hH
L$@I
D$pH
D$0A
D$(H
D$xH
f#D$x
D$xt
u-fD!
L$03
D$@H
D$ H
smHc
\$0H
l$8H
sSHc
` AUH
\$0H
t$8H
|$@L
d$HH
L$HH
T$@A
\$ ;
}kLc
\$@H
t$HH
t$8H
\$0H
AUAVAWH
|$ A
t$(H
t$PH
|$XL
d$`H
0A_A^A]
HcM H
VWATH
\$@H
l$PH
A\_^
L$ UVWH
\$@A9k
vLH;
@8l$X
`_^]
tCH;
@8l$X
@8l$X
D$8H
l$0L
|$(H
@8l$X
@UATAUH
l$ H
d$ A
MhH3
epA]A\]
L$ A
L$pD
\$PH
t$XH
H!\$ E3
\$@H
\$HH
VWATH
\$`H
0A\_^
\$0H
WATAUH
\$`H
t$hH
0A]A\_
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
R6034
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
R6033
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
R6032
- not enough space for locale information
R6031
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
R6030
- CRT not initialized
R6028
- unable to initialize heap
R6027
- not enough space for lowio initialization
R6026
- not enough space for stdio initialization
R6025
- pure virtual function call
R6024
- not enough space for _onexit/atexit table
R6019
- unable to open console device
R6018
- unexpected heap error
R6017
- unexpected multithread lock error
R6016
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
R6009
- not enough space for environment
R6008
- not enough space for arguments
R6002
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
Invalid parameter passed to C runtime function.
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
( 8PX
700WP
`h````
xpxxxx
('8PW
700PP
`h`hhh
xppwpp
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
July
June
April
March
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
IsWow64Process
alwo
p Pf
E%C
GetSystemTimeAsFileTime
GetModuleFileNameW
SetErrorMode
GetFileAttributesW
GetTempPathW
MoveFileW
GetWindowsDirectoryW
DeleteFileW
GetCurrentProcessId
GetTempFileNameW
GetFileSize
MoveFileExW
WriteFile
ReadFile
CreateFileW
GetLastError
CloseHandle
ExitProcess
VirtualQuery
CreateProcessW
VirtualFree
SetLastError
VirtualAlloc
Process32FirstW
Process32NextW
CreateToolhelp32Snapshot
GetEnvironmentVariableW
GetCurrentProcess
GetComputerNameW
GetModuleHandleW
WideCharToMultiByte
GetVersionExW
GetProcAddress
LocalAlloc
LocalFree
FindResourceW
LoadResource
SizeofResource
LockResource
HeapFree
HeapAlloc
HeapReAlloc
GetStartupInfoW
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
HeapSetInformation
HeapCreate
GetStdHandle
GetModuleFileNameA
OutputDebugStringA
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
GetCurrentThreadId
FlsAlloc
GetCPInfo
GetACP
GetOEMCP
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
DeleteCriticalSection
QueryPerformanceCounter
GetTickCount
LeaveCriticalSection
EnterCriticalSection
RtlUnwindEx
InitializeCriticalSectionAndSpinCount
LoadLibraryW
SetFilePointer
GetConsoleCP
GetConsoleMode
MultiByteToWideChar
Sleep
LCMapStringW
GetStringTypeW
SetStdHandle
WriteConsoleW
VirtualProtect
SetThreadStackGuarantee
GetSystemInfo
FlushFileBuffers
KERNEL32.dll
wsprintfW
USER32.dll
CryptAcquireContextW
CryptDeriveKey
CryptReleaseContext
CryptGenRandom
CryptEncrypt
CryptCreateHash
CryptDestroyKey
CryptDecrypt
CryptDestroyHash
CryptHashData
OpenProcessToken
GetUserNameW
GetTokenInformation
EqualSid
AllocateAndInitializeSid
FreeSid
ADVAPI32.dll
CoTaskMemFree
CoCreateInstance
CoUninitialize
CoInitializeEx
ole32.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
mscoree.dll
(null)
USER32.DLL
((((( H
h(((( H
H
CONOUT$
kernel32
https
https
https
version
%s%s%d%d%s
COMMONPROGRAMFILES(x86)
<Process pid=%d ppid=%d threadCount=%d %s\>
%s\%s
rundll
rundll32
rundll32
BINARY
Microsoft Enhanced Cryptographic Provider v1.0
Microsoft Enhanced Cryptographic Provider v1.0
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+-
Microsoft Enhanced Cryptographic Provider v1.0
Microsoft Enhanced Cryptographic Provider v1.0
Process id: %lu
%s/%s%s
%s\Temp\%s
%s%s
%s%d%dupdate.xml
%s/%d%dupdate.xml
%s/uploads/%d%d%d%d%d%d%d%d%d%s
%s %s%s